Best Blackhat Forum

Full Version: [GET] WordPress Price Comparison Plug-In
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Salespage
Code:
http://www.comparipress.com/

Download
Code:
http://www.mediafire.com/?bi3sgkv8vlivxkj

Virus Total
Code:
http://vscan.novirusthanks.org/analysis/b410ad37a6c8f8a2d1c12a6ce8261762/Y29tcGFyaXByZXNzLXppcA==/

Not checked yet, so please do your own virus scan. Looks pretty cool though. Reviews welcome to keep the thread going.

Do NOT say thanks, I really don't care :p
Use this mediafire link if every links above doesn't work.

http://bestblackhatforum.com/Thread-GET-...#pid202881
Above Share from Jonathan is INFECTED

Contains offsite content fetching code
Please remove from your site and replace

Cleaned Version:
Code:
http://uploadmirrors.com/download/6ACY6ZIV/com_pari_press.zip
VT: Clean 0/42
Code:
https://www.virustotal.com/file/9f30000543c7f1862b0ee58ff7daa334de337fa5b7eb103a46756b903a464b18/analysis/1341739481/

Cheers,
Si
please reup this someone
(07-08-2012 07:31 PM)simey69 Wrote: [ -> ]Above Share from Jonathan is INFECTED

Contains offsite content fetching code
Please remove from your site and replace

Cleaned Version:
Code:
/download/6ACY6ZIV/com_pari_press.zip
VT: Clean 0/42
Code:
https://www.virustotal.com/file/9f30000543c7f1862b0ee58ff7daa334de337fa5b7eb103a46756b903a464b18/analysis/1341739481/

Cheers,
Si
Thanks for clear things up Si. Appreciate that. Do you mind if telling me how to check for bug so that I can share "clean" stuff next time? I just want to contribute something to this community. Sorry guys, I will be more alert next time.
Hi Jonathan,

No problem - thanks for clearing it away.
There are a lot of these infected shares right now, it's very, very easy to pick up an infected product, specially WP themes or plugins.

It has to be a manual check, as the infection passes right through online and local AV scanning.

it's typically a simple curl call routine, in functions.php or header.php that goes offsite to another domains and typically fetches a javascript file - normally jquery(and similar).js

A few other people have asked me also and I'm putting together a quick note to show how to spot them, my time is very short at the minute, so taking a litle time, but will be released to all soon.

Cheers,
Si
Thanks for this theme, i will download it now :p
Above link is working fine, heres the RS link.

Code:
https://rapidshare.com/#!download|68p1|1413891619|com_pari_press.zip|1912|0|0
Reference URL's